Switch the merge style to fast-forward-only and protect main #79
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#79
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #77. Blocked by the merge-path proof.
Why
There are zero protected branches on this repository.
CLAUDE.md's rule —"A plan is worked in its own worktree, on its own branch, and never committed to
maindirectly" — is an honour system, and that document records a sessionbreaking it: three commits of in-progress work straight onto the deployment
trigger, then a completion report that never checked CI. It calls the outcome
"luck rather than method."
mainis the deployment trigger.promotemoves:stableand every hostadopts within a minute.
What to do
DefaultMergeStyle:merge→fast-forward-only.AllowFastForwardOnlyis already
trueon the repo, so this is a default change, not a capabilityone. It preserves the linear history
CLAUDE.mdasks for: "a merge commit fora one-branch plan reads as noise a year later."
main: require a pull request, and require thebuildande2echecks green before merge.
PRs are merged by hand. All 15 so far were closed, not merged, and applied
some other way; that path disappears under protection.
Watch for
Protection must not lock out
publish-plugin.mjsor any release automation thatpushes. Check what pushes to
maintoday before turning it on.Done, on 23 September 2026.
main:enable_push=false,apply_to_admins=true,block_on_outdated_branch=true,required_approvals=0. Required checks:CI / build (pull_request),CI / e2e (pull_request),Release note / release-note (pull_request). Theprotected_branchrow confirms it.fast-forward-only, confirmed in therepo_unitconfig.main, because a success there would be a release.automergeType: pr,platformAutomergeandautomergeStrategy: fast-forward, plus aNONErelease note (#115). It has no push exemption.POST /pulls/<n>/merge {"Do":"fast-forward-only"}. One caveat for automation: right aftermainmoves, the next merge can return a transient405 Please try again later, and a retry 5–10 s later succeeds.The rule was applied at
main=ea78644, which isWORKFLOW_EPOCHinscripts/changelog.mjs.